Buffer Overflow Vulnerability in Free Software Foundation lwIP
CVE-2020-22283

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
22 July 2021

What is CVE-2020-22283?

A buffer overflow vulnerability exists in the icmp6_send_response_with_addrs_and_netif() function of Free Software Foundation lwIP, allowing attackers to potentially exploit crafted ICMPv6 packets to gain access to sensitive information. This vulnerability highlights the importance of robust input validation and packet handling within network protocols. Users of affected lwIP versions should take immediate steps to implement security updates to mitigate the risk of exploitation.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.